Details
The AcquireDaemonLock function in ipcdUnix.cpp in Sun Innotek VirtualBox before 2.0.6 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/.vbox-$USER-ipc/lock temporary file.Novell Bugzilla entry: 448240 SUSE Security Advisories:
- SUSE-SR:2009:004, published Tue, 17 Feb 2009 10:00:00 +0000
- SUSE-SR:2009:004 , published Tue, 17 Feb 2009 10:00:00 +0000
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| openSUSE 10.3 |
| ZYPP Patch Nr: 5990 SAT Patch Nr: 513 |
| openSUSE 11.0 |
| ZYPP Patch Nr: 5990 SAT Patch Nr: 513 |
| openSUSE 11.0 |
| ZYPP Patch Nr: 5990 SAT Patch Nr: 513 |